We are looking for a Lead DevSecOps Engineer to launch and lead our Platform & Cloud Security function. This is a rare opportunity to set the standards from scratch and shape how security is embedded into a modern, high-load, cloud-native environment.
Requirements
- Establish the DevSecOps function at Playson, defining best practices and security standards across the Platform Tribe.
- Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning, container scanning).
- Harden infrastructure and runtime environments (Linux, Docker, Kubernetes/EKS, RBAC).
- Design and enforce cloud security controls in AWS (IAM least-privilege, GuardDuty, Security Hub, encryption at rest/in transit).
- Define and maintain IaC security policies (Terraform/Terragrunt, drift detection, policy-as-code).
- Implement and manage secrets management solutions (Vault, AWS Secrets Manager).
- Build centralized security monitoring & alerting (Datadog, ELK, CloudWatch, SIEM/SOAR).
- Lead vulnerability management and threat modeling practices.
- Automate workflows through scripting (Python, Bash).
- Partner with backend, infrastructure, and platform engineers to embed security in design & delivery.
- Contribute to compliance readiness (ISO 27001, GDPR, PCI-DSS).
- Act as a security subject-matter expert, mentoring engineers and raising awareness.
- Continuously evaluate and implement new security tools and approaches.
Benefits
- Compensation at top industry standards
- Quarterly bonuses based on transparent evaluation
- Remote-first flexibility and adaptable working hours
- Unlimited paid vacation & sick leave
- Comprehensive medical insurance (for you and your partner)
- Financial support for major life events
- Professional growth budget for courses, training, and certifications